← back
CVE-2020-8292CWE-79

CVE-2020-8292

3Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackepss 0.9%
exploitation probability
0.9%top 42% of all CVEs
observed exploitation
nono source reports it
Rocket.Chat server before 3.9.0 is vulnerable to a self cross-site scripting (XSS) vulnerability via the drag & drop functionality in message boxes.
Affected products
n/a · Rocket.Chat server